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Abstract 

In this paper, we introduce a new public quantum interactive proof system and the first 
quantum alternating Turing machine: qAM proof system and qATM, respectively. Both are 
obtained from their classical counterparts (Arthur-Merlin proof system and alternating Tur- 
ing machine, respectively) by augmenting them with a fixed-size quantum register. We fo- 
cus on space-bounded computation, and obtain the following surprising results: Both of them 
with constant-space are Turing-equivalent. More specifically, we show that for any Turing- 
recognizable language, there exists a constant-space weak-qAM system, (the nonmembers do 
not need to be rejected with high probability), and we show that any Turing-recognizable lan- 
guage can be recognized by a constant-space qATM even with one-way input head. 

For strong proof systems, where the nonmembers must be rejected with high probability, 
we show that the known space-bounded classical private protocols can also be simulated by 
our public qAM system with the same space bound. Besides, we introduce a strong version of 
qATM: The qATM that must halt in every computation path. Then, we show that strong qATMs 
(similar to private ATMs) can simulate deterministic space with exponentially less space. This 
leads to shifting the deterministic space hierarchy exactly by one-level. The method behind the 
main results is a new public protocol cleverly using its fixed-size quantum register. Interestingly, 
the quantum part of this public protocol cannot be simulated by any space-bounded classical 
protocol in some cases. 



*A preliminary report on some contents of this paper was |YSlla| . 
'The author was partially supported by FP7 FET-Open project QCS. 



1 Introduction 



Anne Condon, in her famous PhD thesis |Con89j . introduced a general computational model, i.e. 
probabilistic game automaton, that unifies many important computational models and concepts: 
Alternation of Chandra, Kozen, and Stockmeyer |CKS81| . private alternation of Reif |Rei84] . 
Arthur-Merlin games of Babai [Bab 85], interactive proof systems of Goldwasser, Micali, and Rack- 
off [GMR89J, game against nature of Papadimitriou |Pap85| , etc. In this framework, Arthur- Merlin 
(AM) proof systems and alternation are the "weakest", since both are the games with complete 
information. In this paper, we introduce two new games by augmenting these two models with a 
fixed-siz^] quantum register, namely qAM and q- alternation, respectively. We focus our attention 
to space-bounded computation, and obtain the following surprising results: Both new games with 
constant space are Turing- equivalent. 

Interactive proof (IP) systems and AM proof systems were introduced by Goldwasser, Micali, 
and Rackoff [GMR85] and Babai [Bab85], respectively. In time-bounded computation, it was shown 
that the class of languages having a polynomial-time IP or AM system is identical to PS PACE 
|Sha92j . In space-bounded computation, IP systems are more powerful than AM systems for any 
space-bound jCon89[ ICon9H IDS92j . e.g. the class of languages having a logarithmic-space AM 
system is identical to P, and the class of languages having a logarithmic-space IP system is a 
superset of EXPTIME. It was also shown that [CL89] for any Turing-recognizable language, there 
exits a constant-space u>eaA0-IP system. 

There are many different definitions of quantum interactive proof (QIP) systems |Kni96l [Kit99|, 
IWat99a[ IAN02[ IMW05] , In time-bounded computation, similar to the classical case, the class of 
languages having a polynomial-time QIP system were shown to be identical to PS PACE [JJUWll] . 
In space-bounded computation, the only published work belongs to Nishimura and Yamakami 
[NY09] . Their results, unfortunately, are model-dependent, and so do not reflect the full power of 
QIP systems since they use some restricted quantum automaton models as the verifiers. 

Our qAM proof system is the first public space-bounded QIP system, and we present the first 
non-trivial results on space-bounded QIP systems. We show how a fixed-size quantum register leads 
to unexpected increase in the computational power of a public proof system. Our main result on the 
qAM system is that there exists a constant-space weak-qAM protocol for any Turing-recognizable 
language. In the classical case, a similar result is known for constant-space weak private protocols 
|CL89| . However, our protocol is not only public but also has perfect-completeness. Our second 
result is that for any known s(n) space-bounded private protocol, there exists an equivalent s(n) 
space-bounded qAM protocol, where s(n) S 0(1) U 0(log(n)) is space-constructible. Therefore, we 
can say that logarithmic-space is sufficient for qAM systems for any language in EXPTIME. 

Alternation was introduced independently by Chandra and Stockmeyer [CS76] and Kozen 
[Koz76] as a generalization of nondeterminism. It was shown that alternation shifts the deter- 
ministic hierarchy 

LCPC PSPACE C EXPTIME C EXPSPACE 

by exactly one level [CKS81]. On the other hand, the class of languages recognized by alternating 
finite automata is still the regular languages jCKSSl] . Reif |Rei84] introduced private alternation by 
assuming that universal player can hide some information from the existential player, and showed 
that private alternation shifts the deterministic space hierarchy 

L C PSPACE C EXPSPACE 

The size of the register does not depend on the length of the input. 

2 The verifier does not need to halt with high probability for the nonmembers of the corresponding language. 



1 



by exactly one level. 

Our q-alternation is the first definition of alternation in the domain of quantum computation. 
Our main result on q-alternation is that one-way q-alternating finite automata can recognize any 
Turing-recognizable language. In the classical case, the class of languages recognized by any space- 
bounded (private) ATMs is a proper subset of decidable languages |Rei84j . Since q-alternating 
machines may not halt the computation in every path, we also introduce the strong version of 
q-alternation by forbidding infinite computations. Then, we show that strong q-alternation, similar 
to private alternation, shifts the deterministic space hierarchy by exactly one level. 

2 Preliminaries 

For any string x, \x\ is the length of x and x[j] is its j th symbol, where 1 < j < \x\. is the 

blank symbol. Moreover, we represent O(l) with 1 and 0(log(n)) with log. 

We assume that the reader is familiar with deterministic, nondeterministic, and alternating 
Turing machines, (DTM, NTM, and ATM, respectively, jl and their time- and space-bounded com- 
plexity classes AfTIME and <YSPACE, where X is "D", "N", and "A", respectively; and, the following 
standard classes: 

• p = u fc>0 DTIME(n k ) and EXPTIME = U fc>0 DTIME(2°( nk )); 

• L = DSPACE(log), PSPACE = U fc>0 DSPACE(n k ), and EXPSPACE = U fc>0 DSPACE(2 o ( nk )); 

• AL = ASPACE(log) and APSPACE = U fc>0 ASPACE(n k ). 

In the following part, we provide the necessary background, based on [DS921 ICon93j . for the 
proof systems. For a detailed survey on space-bounded interactive proof systems, we refer the 
reader to |Con93j . An interactive proof system (IPS) consists of a prover (P) and a verifier (V). 
The verifier is a (resource-bounded) probabilistic Turing machine having a read-only input tape, 
a read/write work tape, and a source of random bits. Each head has two-way access to its tape. 
The states of the verifier are partitioned into reading, communication, and halting (accepting or 
rejecting) states, and it has a special communication cell for communicating with the prover, where 
the capacity of the cell is finite. 

The one-step transitions of the verifier can be described as follows. When in a reading state, 
the verifier firstly flips an unbiased coin and then determines its next configuration based on the 
symbol under the tape heads, the state, and the outcome of the coin flip. When in a communication 
symbol, The verifiers writes a symbol on the communication cell with respect to the current state. 
Then, in response, the prover writes a symbol in the cell. Based on the state and the symbol 
written by prover, the verifier defines the next state of the verifier. 

The prover P is specified by a prover transition function, which determines the response of the 
prover to the verifier based on the input and the verifier's communication history until then. Note 
that this function does not need to be computable. 

For a given input x, the probability that (P, V) accepts (rejects) x is the cumulative accepting 
(rejecting) probabilities taken over all branches of the verifier. The prover-verifier pair (P, V) is an 
IPS for L with error probability e < \ if 

1. for all x G L, the probability that (P, V) accepts w is greater than 1 — e, 

2. for all x ^ L, and all provers P* , the probability that (P*, V) rejects x is greater than 1 — e. 
3 We refer the reader to |Rei84| for the details of private ATMs although it is not necessary to follow the content. 
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These conditions are known as completeness and soundness, respectively. Now, we define some 
variants of IP systems by restricting and/or relaxing the above conditions. 

The prover- verifier pair (P, V) is an weak-IPS for L with error probability e < \ if we relax the 
soundness condition (2) as follows: 

2'. for all x ^ L, and all provers P*, the probability that (P*, V) accepts x is at most e. 

The prover- verifier pair (P, V) is a (weak or not) IPS having perfect completeness for L if we 
restrict the completeness condition (1) as follows: 

1'. for all x S L, the probability that (P, V) accepts x is exactly equal to 1. 

An Arthur-Merlin (AM) proof system (or a public-coin IPS) is a special case of IPS such that 
after each coin toss, the outcome is automatically written on the communication cell, and so the 
prover can have complete information about the computation of the verifier. 

We will use IP(-) and AM(-) to represent the space-bounded complexity classes for IP and AM 
systems, respectively. Note that the space bound is always defined on the verifiers. The ones having 
perfect-completeness will be shown by IPi(-) and AMi(-), respectively. We will use prefix "weak-" 
to represent their "weak" versions. 

Some known facts, related to our results, on AM and IP systems as given below. (We also refer 
the reader to Appendix [A] for the details of some private protocols.) 

Fact 1. \CL88i I Con89l \DS9^ For any space- constructible s(n) = fi(logn), 

weak-AM(s(n)) = AM(s(n)) = ASPACE(s(n)). 

Moreover, weak-AM(l) C weak-AM(log) = AM(log) = P. 

Fact 2. \CL89)/ Any Turing recognizable language is in weak-IP(l). 

Fact 3. JUSMi DTIME(2°( n )) = ASPACE(0(n)) C IPi(l). 

Fact 4. \Con89\ \CL89\ \DS9ty For any space- constructible s(n) = f2(log(n)), 

DTIME(2 2 ° ts(n)) ) = ASPACE(2°( s ( n ») C IPi(s(n)). 
Fact 5. \CL89\j For any space- constructible s(n) = f2(log(ra)) ; 

IPi(s(n)) C IP(s(n)) C ATIME(2 22 ° tS(n)) ). 

As seen from the above facts, private protocols are more powerful than public ones under the 
same space bounds. In case of weak-soundness, the power of the private protocols with finite-state 
verifiers becomes Turing-equivalent, which is never possible for a public protocol with any given 
space bound. 

We will shortly show that the public protocols using a fixed-size quantum register can also imple- 
ment some private protocols under the same space bounds. More specifically, the results presented 
in Facts [3] and H] can also be obtained for qAM systems. Moreover, in case of weak-soundness, our 
new public protocol can also be Turing-equivalent even restricting to perfect-completeness, which 
can never be a case for private protocols with any given space bound due to Theorem [T] (see below). 

Theorem 1. For any space- constructible s(n) G O(log(n)), 

IPi(s(n)) C weak-IPi(s(n)) C ASPACE(2 2 ° (s(n)) ). 

Proof. See Appendix [Bj □ 

Note that Theorem [1] improves the previously known upper bound (Fact [5|) for space-bounded 
IPS with perfect-completeness. 
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3 qAM 



In this section, we give the definition of our new AM system (qAM) and present our results on 
qAM proof systems. 

A qAM ( guantum Arthur-Merlin proof system is an AM system where the verifier additionally 
has a fixed size quantum register. The reading state of the new verifier is as follows: 

A superoperator, determined by the current state and the symbol(s) under the tape 
head(s), is applied to the quantum register, and the outcome of the operator is auto- 
matically written on the communication cell in order to satisfy the complete information 
requirement. Then, the next configuration is determined based on the the current state, 
the symbol(s) under the tape head(s), and the observed outcome. For any deterministic 
transition, the verifier applies an identity operator on the register. We refer the reader 
to Figure Q] for the details of superoperators. 

Note that the verifier no longer needs a classical random sourceJl We will use qAM(-) and qAMi(-) 
to represent qAM counterparts of AM(-) and AMi(-), respectively. Prefix "weak-" is also applicable 
to qAM(-) and qAMi(-). We give a simple qAM protocol for the well-known NP-complete language 
SUBSET-SUM in Appendix 

The most general quantum operator is a superoperator, which generalizes stochastic and unitary operators and 
also includes measurement. Formally, a superoperator £ is composed by a finite number of operation elements, 
£ — {Ei, . . . , Ek}, satisfying that 

k 

^2E}E i = I, (1) 

i = l 

where k £ Z + and the indices are the measurement outcomes. When a superoperator, say £ , is applied to the 
quantum register in state i.e. £(]ij))), we obtain the measurement outcome i with probability pi = (ipi 
where \ipi), the unconditional state vector, is calculated as \tfii) — Ei\%p) and 1 < i < k. (Note that using 
unconditional state vector simplifies calculations in many cases.) If the outcome i is observed (pi > 0), the new 

state of the system is obtained by normalizing which is — ^=r- Moreover, as a special operator, the 
quantum register can be initialized to a predefined quantum state. This initialize operator, which has only one 
outcome, is denoted £ . In this paper, the entries of quantum operators are defined by rational numbers. Thus 
the probabilities of the outcomes are always rational numbers. 

Figure 1: The details of superoperators 

Knowledgeable readers will have noticed that, when the verifier is restricted to use constant 
space, the qAM system is actually the quantum counterpart of the finite automaton with both 
nondeterministic and probabilistic states of Condon et. al. [CHPW98] . and that if we remove 
the communication with the prover as well we end up with a finite automaton with quantum and 
classical states (2QCFA) of Ambainis and Watrous [AW02] . 

In our qAM protocols (and later in our q-alternation simulations), we use some non-unitary 
transformations to implement our main tasks. We define our superoperators based on these trans- 
formations. Let E\, . . . , Ek be some of these transformations. We can obtain a superoperator £ 
based on them by defining some additional transformations E^+i, ■ ■ ■ ,Ek+y such that 

£ = I ■ ■ ■ , -jE k , j E k+l, ■■■ , j E k+k>^j 

4 The small "q" indicates that the verifier has a "very small" (possible the smallest) quantum resource. 
5 For example, the superoperator £ — {Eh! = -^1, Eh 2 = ^I,Et x = ^I,Et 2 = \l} always produces the outcomes 
head ("hi" or "fe) and tail ("ti" or "fo") with probability |. 
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satisfies Condition Q] in Figure [T] for a convenient d > 1, where A;' > 00 We call • • • , \Ek] 

the main operation elements and {^Ek+i, ■ ■ ■ , ^-Sfc+fc'} auxiliary operation elements. Moreover, 
in our protocols, the computation continues on the quantum register only when the outcomes of 
some main operation elements are observed. On the other hand, the current computation on the 
quantum register is always terminated/restarted with discarding the current content of the register 
when the outcome of an auxiliary operation element is observed. Therefore, the details of the 
auxiliary operation elements can be omitted from the description of the protocols. 

In the following part, we present our qAM protocols. We begin with a constant-space weak- 
qAM protocol having perfect completeness for any given Turing-recognizable language. We present 
our result by giving a new public protocol simulating a given DTM. Contrary to the classical casejll 
our simulation technique can also be applicable to the case of strong-soundness. Therefore, after 
making certain modifications, we present our other space-bounded qAM protocols. Note that, all 
of our qAM protocols have perfect- completeness® Interestingly, this property allows us to use the 
same techniques for q- alternation after making some restrictions and modifications. 

Theorem 2. Any Turing recognizable language is in weak-qAMi(l) . 

Proof. Let L be a Turing recognizable language and D be a single-tape DTM recognizing L. We 
will construct a weak-qAM proof system (P, V) for L with perfect completeness, where V is a finite 
state verifier. 

We begin with some details of V. Q containing q\ (the initial state), q a (the accepting state), 
and q r (the rejecting state) is the set of states, T containing # is the tape alphabet, and T' = Q{JT, 
called configuration alphabet, where Q and T are disjoint sets and $ ^ T. Note that V contains at 
least 5 elements. Any configuration of T> is of the form uqv (T> is in q and the tape head is on the 
leftmost symbol of v), where q G Q and uv E #(T)*#. The unnecessary blank symbols are always 
dropped from the descriptions of configurations. For a given input string x, the initial configuration 
is represented as qi#x#. 

The main protocol is executed in an infinite loop and each iteration (round) is composed by 
the following: (i) The verifier requests the computation (a sequence of configurations starting from 
the initial configuration) of T> on the given input, say x, from the prover. (ii) Against the cheating 
provers, the verifier checks the correctness of the computation and rejects x if it detects a defect in 
the computation, (iii) When it encounters a halting configuration, the verifier mimics the decision 
of this (halting) configuration. 

Let w be the string obtained from the prover in a single round. The verifier expects w as 
ci$$C2$$C3$$ • • • , where (PI) Cj's (i > 0) are some configurations of T>, (P2) c\ is the initial con- 
figuration, and (P3) Cj+i is the successor of q in one step for any i > 0. (We use double $ for 
pedagogical reasons.) Note that w can be an infinite string. The verifier can check PI and P2 
deterministically, and x is rejected immediately if one of them fails. Therefore, in the following 
part, we assume that w satisfies both PI and P2 and each configuration ends with "$$". 

The non-trivial part is to check P3 for each i > 0, i.e. whether Cj+i is identical to next(cj), 
where next(cj) is the single-step successor of Cj. This is where the quantum register comes into play. 
The idea behind is to encode next(cj) and Cj+i into the amplitudes of two states on the register, 
and then to subtract them, and to reject x with the resulting amplitude^ We call this procedure 



6 We refer the reader |YS10I lYSllbj for similar procedures. 

7 In classical case, to show universality of constant-space weak-IP systems, a simulation of two-way finite automaton 
with two-counters was given |CL89| . Since the complexity classes are defined by Turing machines, this technique does 
not seem to be applicable to the case of strong-soundness. (See also Appendix lA"t 

8 Two-sided bounded error is necessary for the universality of constant-space weak-IP systems due to Theorem [T] 
9 In fact, the encoding part can also be implemented by a probabilistic system but the aforementioned subtraction 

is not possible in classical systems! 
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successor-check. The i th successor-check compares next(cj) and Cj+i. As will be detailed below, 
whenever Cj+i = next(cj) (for all defined i > 0), the input is never rejected by a successor-check. 
Thus, once a halting configuration is obtained from the prover, the only decision is made based on 
it. Otherwise, i.e. 3i > s.t. Cj+i / next(cj), x is rejected by the i th successor-check. We show 
that such a reject probability is sufficiently greater than any accept probability in a single round. 

In the remaining part, we will give the details of a single round and the analyses of the protocol. 
The verifier requests the computation of T> on x symbol by symbol from the prover, and it uses 
a 3-symbol buffer to parallelly encode the legal successor of the presently scanned configuration. 
The verifier uses a 4-state quantum register, qi,...,q&, which is set to \ipi : o) = (1 0) T at 
the beginning of each round. The configurations are encoded in base-m, where m = \T'\ + 1. Each 
symbol of V is associated with a different positive integer. Thus, any configuration c,, (i > 0) can 
be represented by a |q (-length number in base-m. We use the same symbol for both the encoded 
string/symbol and its encoding. The verifier applies one superoperator per symbol. When the 
outcome of an auxiliary operation elements is observed, the verifier terminates the current round 
and initiates a new round. The tasks implemented by the main operation elements reduce the 
amplitudes with -j < 1. Therefore, after applying each superoperator, a new round is initiated 
with some probability. In other words, a round can continue only with a small probability. The 
complete details of the superoperators and the related operations are given at the end of the proof 
due to their technicalities. 

Let U be the length of ci$$C2$$ • • • Cj$$ {i > 0). By processing ci$$, i.e. a series of superoperators 
£i t l, ■ ■ ■ )£i |ci$$| are applied to the register, next(ci) is encoded into the amplitudes of \q2). Then, 
the quantum state become^ 



2,0/ 



/ 1 \ 

next(ci) 


V o / 

Similarly, by processing C2$, C2 and next(c2) are encoded into the amplitudes of \qs) and \q±) 
respectively: 



l^2,|c 2 $|) 



d 



( 1 \ 

next(ci) 

C2 

\ next(c 2 ) J 

After processing one more $, the first successor-check is finalized: The corresponding superoperator 
has two main operation elements. The first one is responsible for comparing next(ci) and C2, and 
subtracts the amplitudes of \q2) and \q3). Its outcome is observed with probability 

1\ 21 ' 2 

-J (next(ci) - c 2 ) 2 , 

which is also the rejecting probability of the first successor-check. The second main operation 
element is determined conditionally. If next (02) is an accepting (a rejecting) configuration, then it 
selects only the amplitude of \qi), the outcome of which is observed with probability Q) 2 ' 2 - This 
probability is also the accepting (rejecting) probability of the round. Since the computation is 
terminated due to the outcomes of both operation elements, the round does not continue in this 



Note that, unconditional state vectors facilitate the calculations. The probabilities can be calculated directly. 
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case. If next(c2) is not a halting configuration, the round continues with the next successor-check. 
Thus the quantum state becomes 



\t 



3,0/ 



1 

next(c2) 





\ 



One can easily verify that if the prover is cheating about C2, the input is rejected with a probability 
at least m 2 Q) 2 ' 2 since both next(ci) and C2 end with a # and they must be disagree on at least one 
digit. If the prover is honest, the decision is given only if next(c2) is a halting configuration, whose 
probability is at least m 2 smaller than the above rejecting probability. The other successor-checks 
are executed exactly in the same way (see the end of the proof). 

The analysis of the protocol is as follows. If x G L, then P always sends the correct computation 
of T> on x to V, say ci$$C2$$ • • • $$c<$$ such that next(ct) is an accepting configuration. Then V 
never rejects but accepts x with probability Q) 2 '' in each round. So, x is accepted exactly by V. 

If x ^ L, then the only case in which V accepts x is that P* send a computation of some 
nonhalting configurations ci$$C2$$ • • • $$Q'$$ such that next(Q') is an accepting configuration, 
where t' > 1. Since x ^ L, there must be an i (1 < i < t') such that next(cj) ^ (H+i- Therefore, 
x is rejected with probability at least m 2 times greater than the accepting probability in a single 
round. In other words, the overall accepting probability can be bounded above by m 'l +1 ■ This 
bound can be easily reduced to any desired value by selecting a greater m value. 

Now, we give the omitted details of the superoperators and the related operations below. Re- 
member that li is the length of ci$$C2$$ • • • Cj$$ and the quantum state is set to 



1,0/ 



/ 1 \ 




V o y 

at the beginning of each round. As described before, we omit the details of each auxiliary operation 
element, and a new round is initiated when the outcome of such an operation element is observed. 

For each symbol of w\ = c\%%, the verifier applies \w\\ superoperators, £1,1, . . . ,£\\ Wl u to the 
register, some of the the same. The aim is to encode next(ci) into the amplitudes of \q2). For each 
j G {1, . . . , \c\\ — 1}, the main operation element of £ij is as follows: 



1 

next(ci)[j] 






m 














/ 



For £* 1 j Cl and £ii ci $|, we have the following cases, each of which can be deterministically determined 
and handled by using 3-symbol buffer: 

• If I next (ci) I = |ci| — 1, the main operation elements of £i t \ Cl \ an d £1 i C i$| are as follows: 



/ 1 





V 












/ 



and 



/ 1 




V 












/ 



respectively, since the encoding of next(ci) is finished by superoperator £1 



ki 
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If |next(ci) 



|ci|, the main operation elements of £i,\ Cl \ and £1 i ci <( 



are as follows: 







f 1 











f 1 














1 


# m 








and — 





1 












d 













d 














• 






V 





o J 






^ o 








o J 




respectively, 


since 


the encodin 


5 of next(ci) is 


finished by superoperator £\\ Cl \- 


the last symbol of any configuration 


is a blank symbol.) 










If next(ci) 


= l c il 


+ 1, the main operation elements of £ 




and £\ 


| C1 $I are as fc 




( 


1 














/ 1 








°\ 


1 


next(ci)[|ci|] 


rn 








and — 


# 


m 








d 


















d 



























o J 






I o 








o / 



(Note that 



respectively, since the encoding of next(ci) is finished by superoperator £i,|ci|+i- 
The main operation elements of £ii Cl $$| is as follows: 



/ 1 




V 



Thus, after applying superoperators £ij's (1 < j < \w\ 

1^2,0) = 



\ 

1 

0' 

/ 

), the state vector of the register becomes 
1 \ 

(2) 



V 



next(ci) 





/ 



We continue with the block W2 = C2$$. In fact, the tasks implemented in this part are the 
same for any other block w% = Cj$$ (i > 2). Similar to the above case, for each symbol of u>2, 
the verifier applies \w2\ superoperators, £2,1, ■ ■ ■ , £2,\w 2 \-> ^° the register, some of which can be the 
same. Remember that before starting to apply any operator, the unconditional state vector is \ip2,o) 
(Equation [5} . The aims in this block (1V2) are as follows: 

1. By processing C2$, 

(a) to encode C2 into the amplitudes of ^3) and 

(b) to encode next (02) into the amplitudes of ^4). 

2. By processing the second $, 

(a) to finalize the 1 st successor-check, 

(b) to accept or reject the input if next(c2) is an accepting or a rejecting configuration, 
respectively; and, to start 3 rd successor-check if next(c2) is not a halting configuration. 
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The details of superoperators to encode c 2 and next(c2) are similar to the ones given above. For 
each j £ {1, . . . , |c2 1 — 1}, the main operation element of £ 2 j is as follows: 





( 


1 








°\ 


1 







1 








d 









771 







\ 


next(c 2 )[j] 








m / 



For £ 2 ,\c 2 \ an d ^2,|c2$|) we have the following cases: 

• If I next (02) I = I C2 1 — 1, the main operation elements of £" 2 j C2 i and £ 2 ,\ C2 $\ are as follows: 
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respectively, since the encoding of next (02) is finished by the superoperator £ 2 
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If |next(c2)| = I C2 1 , the main operation elements of f 2 i C2 i and ^2Jc 2 $| are as follows: 
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respectively, since the encoding of next(c2) is finished by the superoperator £" 2 i C2 i - 

If |next(c2)| = I C2 1 + 1, the main operation elements of <?2.|c 2 | an d &2,\c 2 %\ are as follows: 
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\ next(c 2 )[|c 2 |] 

respectively, since the encoding of next (02) is finished by superoperator f^lcal+i- 



Thus, before applying £ 2 



the state vector becomes as follows: 



l^2,|ea$| 
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next(ci) 
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\ next(c 2 ) j 



(3) 



Operator <?2,|c2$$| has two main operation elements. This first one is responsible to finalize the 1 
successor-check: 
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The associated action of this operation element is to reject the input. Therefore, the input is rejected 
with probability 

1\ 2 ' 2 2 
- ) (next(ci) - c 2 ) 



which is zero if the check succeeds (next(ci) = c 2 ) and is at least 



2l 2 



m 



if the check fails (next(ci) 7^ C2). Since the last symbol of next(ci) and C2 are the identical, the 
value of |next(ci) — C2I can be at least m. 

The second main operation element is determined by the type of next (02): 

• If it is an accepting (a rejecting) configuration, then the following operation element is applied: 



/ 1 













0\ 



/ 



The associated action of this is to accept (reject) the input. Therefore, the input is accepted 
(rejected) with probability 

l\ 2l 2 

Note that the round is certainly terminated in this case. 
• If it is not a halting configuration, then the following operation element is applied: 
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The associated action of this is to continue the round, and so to initiate the 3 rd successor- 
check. The state vector becomes 



l^3,o) 



h 
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next(c2) 





\ 



Note that if the prover never sends $$ symbols, then no decision is given. 

The tasks for block W3 = 03$$ is exactly the same as for block u>2 = C2$$, and the tasks for 
block W4 = 04$$ is exactly the same as for block W3 = 03$$, and so on. Therefore we can generalize 
it for a generic block uii = Cj$$, where i > 2. The state vector is 



/ 1 

next(Q_i^ 
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at the beginning. The aims are as follows: 
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1. By processing a$, 



(a) to encode c% into the amplitudes of \qz) and 

(b) to encode next(cj) into the amplitudes of I34). 

2. By processing the second $, 

(a) to finalize the (i — l) st successor-check, 

(b) to accept or reject the input if next (c^) is an accepting or a rejecting configuration, 
respectively; and, to start the (i + l) st successor-check if next(cj) is not a halting con- 
figuration. 

When the (i — l) st successor-check is finalized, the input is rejected with probability 

(next(Q_i) - Ci) 2 , 



1 \ 2/i 



which can be at least 



1 \ 2/^ 
1 > 2 

m 

a 



if next(cj-i) / Cj. If next(cj) is an accepting (a rejecting) configuration, then the input is accepted 
(rejected) with probability 



.d. 

Otherwise, the (i + l) st successor-check initialized with the state vector 



l^,o) 



d 



( 1 \ 

next(cj) 



/ 



□ 



One of the remarkable properties of our protocol is that the quantum register can be in a 
superposition of two successor-checks, which is one of the fundamental and distinctive properties of 
quantum computation. In fact, classical private protocols can also "imitate" this phenomenon: The 
verifier privately selects odd- or even-numbered successor-checks, and so, from the viewpoint of the 
prover, the verifier seems to be in a superposition of two successor-checks (such as, with probability 
2). However, in our protocol, the verifier really is in a superposition and it is independent from 
any prover. This is indeed why our protocol works in a public setting. Therefore, our protocol can 
be seen as a new and elegant evidence on how the superposition phenomenon can become useful in 
terms of complexity theory. 

The main consequence of Theorem[2]is that qAM systems can be more powerful than IP systems: 

Corollary 1. For any space bound s(n), weak-IPi(s(n)) C weak-qAMi(l). 

Now, we turn our attention to the protocols in which the computation always halts with high 
probability. (Note that, our weak-protocol may run forever in some cases, i.e., the simulated 
machine may run forever on the given input, a cheating prover never sends $$ after sending a few 
valid configurations, etc.) In our weak-protocol (above), the input head of the verifier is never 
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used after checking the first configuration. In fact, it can be used to check whether the length 
of a configuration sent by the prover is linear. Thus, the verifier can force the prover to send 
linear-size configurations. So, it can be easily obtained that DSPACE(n) C qAMi(l), i.e. the 
prover sends the computation of a linear-space DTM. If the prover is additionally asked to provide 
nondeterministic choices, this result is extended to that NSPACE(n) C qAMi(l), i.e. the prover 
sends the computation of a linear-space NTM, in which nondeterministic choices are determined 
by the prover. Although it is not trivial as the above two results, we can go one further step: 
ASPACE(n) C qAMi(l), i.e. the prover sends the computation of a linear-space ATM, in which 
nondeterministic choices are determined by the prover and universal choices are determined by the 
verifier. This idea was firstly given by Reif |Rei84| for the simulation of a space-bounded ATM by 
a private ATM, and then used by Condon and Ladner [CL88j . Condon [Con89] . and Dwork and 
Stockmeyer |DS92j for similar simulations. We follow the latest result by embedding the simulation 
idea of Dwork and Stockmeyer |DS92j into our weak-protocol by making some modifications. 

Theorem 3. DTIME(2°( n )) = ASPACE(n) C qAMi(l). 

Proof. Let L be a language in ASPACE(n). Then, there exists a single-tape ATM A recognizing 
L. The components of A is similar to D given in the proof of Theorem [2j (Note that, for an 
ATM, any nonhalting state is labelled as either existential or universal.) We make some additional 
assumptions on A as given in Dwork and Stockmeyer |DS92j (See also Appendix |A|). Tape alphabet 
r, apart from contains another special symbol <f. The input, say x, is given as Qx$, ct is only 
overwritten by the head is not allowed to leave the area between the cent symbols, and any 
non-cent symbol is only overwritten by a non-cent symbol. Thus, any configuration of A is of 
the form uqv such that q G Q and uv G <t(r \ {$}) ^'(t- We assume that A makes an existential 
move after a universal one and vice versa. Moreover, each such a transition leads to exactly two 
branches. In order to fix the running time in each branch, we assume that A has some additional 
deterministic states (i.e. universal states with no branching) to keep a counter to guarantee that 
the decision is always given after making 2 C ' X ' branching transitions. So, we can group non-halting 
states of A into three groups: 

1. existential states, 

2. universal states leading to two transitions, and 

3. universal states leading to one transition. 

The third ones are called deterministic states to prevent confusion. So, the second ones are called 
just universal states. We also assume that each counter operation takes the same amount of steps, 
which is only dependent on the length of input (\x\). So the computation tree of A' on x, denoted 
by Ta(x), has 2 2 ° x leafs, and each path from the root to a leaf has the same depth, where c is an 
appropriate constant. If the leaf is an accepting (rejecting) configuration, then the path is called 
accepting (rejecting) path. 

Now we will describe a qAM proof system (P, V) for L with perfect completeness based the 
qAM system given in the proof of Theorem [2] after making some modifications, where V is a finite 
state verifier. 

The first modification is that the verifier requests a computation path of Ta ( x ) > i- e - a path from 
the root to one of the leafs, from the prover in each round. The format of the computation is the 
same: 

Ci$$C2$$ • ' ' Cj$$Cj_|_l$$ • • • . 
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However, before a successor-check, say the i th one, the verifier should know which branch it follows 
after Cj since the verifier encodes next (ci) during processing Cj$$. Therefore, the verifier should 
know the follow-up branch before obtaining c,,$$. Similarly, the prover should be aware of this 
branch before sending Cj+i. As mentioned earlier, any existential branch is determined by the 
prover and any universal branch is determined by the verifier. One of the convenient way is that 
before communicating on Cj$$, both parties exchange their decisions about which branch is followed 
after Ci. Remark that if Cj is a deterministic branch, then both choices become useless, if it is an 
existential (a universal) one, the choice of the prover (the verifier) becomes useless. The verifier 
makes its choice with equal probability. Therefore, it applies a superoperator having the following 
two main operation elements 

l r 

where outcome "1" ("r") represents the left-branch (right-branch) and / is the identity operator. 

The second modification is that each configuration length is deterministically checked by the 
verifier to be equal to \x\ + 2 by help of the input head. (We denote this property as P4.) If not, 
the computation is terminated and the input is rejected immediately. 

The third modification is about the acceptance probability, which is dramatically made smaller 
when compared to the one in the original protocol. We describe why the original strategy does not 
work with an example. 

Remember that if a round ends with an accepting (a rejecting) configuration in the 
original protocol, then the input is accepted (rejected) with a probability calculated by 
the amplitude of \q\). Suppose that the prover sends a computation of A satisfying Pl- 
P4. Then if the verifier follows the original strategy, the input is rejected (accepted) with 
the same probability at the end of each round since the length of each path is equal in 
this case. If the prover follows a nondeterministic strategy of A that leads to exactly one 
rejecting leaf, then the input is accepted with a high probability although the input must 
be rejected with high probability with respect to this subtree. 

Our new acceptance strategy is as follows. The verifier uses an additional state, q$, on the register. 
When a new round is initiated, the state vector is immediately set to 



/ 1 \ 






V i / 



Then, the amplitude of \q^) is multiplied by 



1 

2rf 



for each configuration in the computation. The input is accepted similar to the original protocol 
but by the amplitudes of Note that after making b branches, the ratio of the amplitude of |<7i) 
to the amplitude of |qs) is 2 6 , and so, any rejecting probability calculated by the amplitude of |<7i) 
is 4 fe times greater than any accepting probability calculated by the amplitude of \qi)- 
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Now, we can analyse our modified protocol. If x G L, then (honest) P always sends a valid 
computation of A on x, and the input is always accepted with a (constant) non-zero probability in 
each round. Therefore, x is accepted by V exactly. 

If x ^ L, there exists always at least one rejecting path whichever nondeterministic strategy is 
followed. As known form the original protocol, if the prover (P*) sends some configurations violating 
any of P1-P4, then the rejecting probability is always sufficiently greater than the accepting one in 
a single round. Therefore, suppose that the prover sends the configurations satisfying P1-P4. Let 
p be the probability of rejecting x at the end of a rejecting path. So, the accepting probability of 
x at the end of an accepting path is equal to 

Since there can be at most 2 2C ^ — 1 accepting paths, a single rejecting probability is sufficiently 
greater than the overall accepting probability. □ 

Theorem 4. For any space- constructible s(n) € 0(log(n)), 

DTIME(2 2 ° (s(n)) ) = ASPACE(2 ^ n ») C qAMi(s(n)). 

Proof. In this case, the verifier can force the prover to send 2°( s ( n ))-size configurations by using its 
classical work tape. The remainder follows from the proof of Theorem [3j □ 

Corollary 2. EXPTIME C qAMi(log). 

Due to Fact [1] and Theorem we can follow that qAM systems (having perfect-completeness) 
are strictly more powerful than any AM system under the same space bound. 

Corollary 3. For any space bound s(n), 

AM(s(n)) C weak-AM(s(n)) C qAMi(s(n)). 



4 q-Alternation 

As mentioned earlier, alternation and AM proof systems are games with complete information. 
Moreover, they could be obviously related to each other, e.g. alternation can be "inherited" from 
AM systems as follows: The verifier is replaced by a universal player and all provers are represented 
by an existential player 

In this section, we introduce the notion of quantum alternation for the first time. We define 
quantum alternation similar to our qAM system, i.e., its quantum part is only a fixed-size quantum 
register and this register can only be accessible by the universal states. We call the model q- 
alternation due to its "very" limited quantum part, and give the definition based on Turing machine, 
q-alternating Turing Machine (qATM). 

A qATM is an ATM augmented with a fixed-size quantum register, based on which universal 
branches are determined. Any configuration of a qATM can be represented by a pair (c, |Y>)), where 
c represent the classical configuration of the machine and \ip) is the state of quantum register. Let 
{ci, . . . , Cfc c } be the transitions determined by the classical transition function of the machine with 
respect to the classical state and the symbol(s) under the tape head(s) in configuration c, where k c 

"We refer the reader to Condon |Con89| for the technical details. 
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is the total number branches. If c is an existential configuration, then only the classical part of the 
qATM is changed, and the following transition(s) is (are) implemented: 



(c, |^)) -> {(ci,|V» I 1 <i<k c }. 

If c is a universal configuration, then both the classical part and the quantum state of the qATM are 
changed: The machine applies a superoperator determined by the classical state and the symbol(s) 
under the tape head(s) in configuration c, £ c = {E C) i, . . . ,E Cj k c }, to the register, i.e. 



|Y>i) = -^7= if Pi / 0, where pi = \ipi) = E C M), and 1 < i < k, 

and then the following transition(s) is (are) implemented: 

(c, -»• {(ci, iV'i)) | Pi > 0, 1 < i < fc c }. 

Note that, the transitions having zero probability (pi = 0) are not implemented^! The computation 
starts when the machine is in the initial classical configuration and the initial quantum state. The 
computation is terminated with the decision of "acceptance" ("rejection") if the machine enters 
an accepting (rejecting) configuration. The acceptance criteria of qATM is the same as ATM. For 
any given input, we have a computation tree representing all moves of the machine. The input 
is accepted if and only if there exists a finite accepting subtree\^ for a nondeterministic strategy 
in this computation tree. If we remove the work tape of a qATM, and restrict the input head to 
one-way, we obtain a one-way q-alternating finite automaton (q-lAFA). 

We begin with a q-lAFA simulation of the qAM protocol given in the proof of Theorem [2j 
Thus, we obtain that q-alternation leads us to simulate any TM even the input head is restricted 
to one-way. 

Theorem 5. Any Turing-recognizable language can be recognized by a q-lAFA. 

Proof. Let L be a Turing-recognizable language, P be a single-tape DTM recognizing L, and (P, V) 
be the qAM system for L, as described in the proof of Theorem [2j It is obvious that V never needs 
to move its input head to the left in a single round. That is, the input head is used only at the 
beginning of each round to check whether the prover sends the valid initial configuration, which 
can be easily be implemented by moving the input head from the left to the right once. We define 
a new one-way finite state verifier V based on V. The only difference between V and V is that 
when the outcome of an auxiliary operation element is observed, V terminates the computation 
with decision of "acceptance", instead of initiating a new round. Thus, V executes only a single 
round (and so V never needs to move its input head to the left). 

The analysis of the proof system (P, V') is as follows. Let x be an input string. If x £ L, the 
computation is terminated in every branch, and the input is accepted by V with probability 1 by 
the help of P. (Remember that (P,V) has perfect-completeness.) If x ^ L, there are two cases 
depending on the prover (P*) strategy and also the behaviour of T> on x: (1) the computation may 
be run forever in some branches, and, (2) the computation is terminated in every branch and the 
input is rejected by V with some non-zero probability . 

Now, based on V', we can easily construct a q-lAFA A recognizing L. The universal states 
of A simulate V and the existential states of A simulate the communications with all possible 



12 In terms of two-person games |Con89| , we can say that the player who makes the universal choices uses a quantum 
register to make its choices, therefore any choice with zero probability can never be a part of that player's strategy. 

13 Each leaf of an accepting subtree is an accepting leaf, a leaf in which the decision of "acceptance" is given. 
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provers. If x S L, there exists a finite accepting subtree whose existential moves correspond to the 
communication with P. If x ^ L, the finite sub-tree(s) can only be possible in the second case 
given above. Obviously, at least one leaf of such a subtree is a reject. Therefore, there is no finite 
accepting subtree for the nonmembers. □ 

Corollary 4. For any space bound s(n), q-lAFAs are strictly more powerful than any s(n) space- 
bounded private ATM. 

Proof. This follows from Theorem [5] and the fact that the class of languages recognized by any 
space-bounded private ATM is a proper subset of decidable languages |Rei84j . □ 

Since the entries of any operation element are rational numbers, any space-bounded qATM 
can be simulated by a DTM in a straightforward way. Due to this fact and Theorem [5l we 
cannot mention a space hierarchy for q-alternation. Moreover, the computation of qATMs may 
not be halted in some paths. Therefore, we define a restricted version of q-alternation: strong 
q-alternation. Any q-alternating machine is a strong one if it halts on every computational path. 
We will denote the related space complexity classes by qASPACE(-), i.e. qASPACE(s(n)) is the class 
of languages recognized by s(n) space-bounded strong qATMs. qAL and qAPSPACE are strong 
q-alternating counterparts of AL and APSPACE, respectively. We show that strong q-alternation 
(similar to private alternation |Rei84j ) shifts the deterministic space hierarchy by exactly one level. 

Theorem 6. For any space- constructible s(n) € Jl(log(s(n))), 

DSPACE(2°( s ( n ))) = qASPACE(s(n)). 

Proof. Prom [CKS81] and Lemma [3] (see below), we can follow that 

DSPACE(2°( s ( n ») C ATIME(s(n)) C qASPACE(s(n)). 
From Lemma [2] (see below) and Savitch's theorem |Sav70| . we can follow that 
qASPACE(s(n)) C NSPACE(2°( s ( n ))) C DSPACE(2°( s ( n ))). 

□ 

Corollary 5. L C qAL = PSPACE C qAPSPACE = EXPSPACE. 

In the remaining part, we give some technical lemmata used in the proof of Theorem [6j We 
begin with showing an upper bound on the running time of a space-bounded strong qATM. 

Lemma 1. For any s(n) € f2(log(n)) ; the running time of a s(n) space-bounded strong qATM can 
be at most 2°^ n ^ . 

Proof. The proof follows from Appendix [Dj □ 

Due to Lemma \T\ we can also provide a nondeterministic space simulation of a given space- 
bounded strong qATM by exponential blow-up. 

Lemma 2. For any space- constructible s(n), if L is recognized by a s(n) space-bounded strong 
qATM A, there exists a 2°^ n ^ space-bounded NTM M recognizing L. 
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Proof. Let x be a given input. The length of any computation path of A on x can be at most 
2 c i s (N) and any configuration length can be at most C2s(|x|), for appropriate numbers c\ and ci- 
We know that if x € L, there exists a nondeterministic strategy that leads to an accepting subtree, 
and, if x £ L, the subtree of each nondeterministic strategy has at least one rejecting leaf (a leaf 
in which the decision of "rejection" is given). J\f nondeterministically implements each strategy of 
A on x, and, for each strategy, traces the corresponding subtree path-by-path by using 2°( s " x "' 
space. Note that 2 0( ~ s( ~\ x ^ space is also sufficient to trace the content of the quantum register in 
a path since in each step, the precision of any amplitude can be increased by at most a constant, 
and so the space to hold the state of the register increases at most by a constant in each step. 

If A/ - detects a rejecting leaf for a strategy, then it rejects the input. If there is no such a leaf for 
a strategy, then it accepts the input. Therefore, if x 6 L, N accepts the input in at least one of its 
nondeterministic branch; and, if x ^ L, the input is rejected in all nondeterministic branches. □ 

Now, we show that the bound given in Lemma [2] is actually tight. 

Lemma 3. For any log-space constructible t(n) £ O(n), if L is recognized by a ATM A running in 
time t(n), then there exists a 0(log(t(n))) space-bounded strong qATM A' recognizing L. 

Proof. We know that any s(n) space-bounded ATM can be simulated by a 0(log(s(n))) space- 
bounded qAM proof system, say (P, V), with perfect-completeness (Theorem [4]). A generic schema 
of this simulation is as follows: 
BEGIN LOOP 

V obtains a computation path of the ATM on the given input from the prover 

V processes this computation and makes a decision with some probability 
IF V makes a decision, THEN the computation (LOOP) is terminated 

END LOOP 

Let x be an input. In this simulation, V can deterministically check weather the length of of 
a configuration sent by the prover is cs(|x|) by using its work tape, where c is an appropriate 
number. On the other hand, the maximum length of a single-round is determined by the prover. 
For example, for a valid computation, a honest prover can send 2°^ s ^ x ^ configurations, and V can 
only count until 0(s(|x|)) by using a "standard" counter. 

If we replace the simulated ATM with our t{n) time-bounded ATM A, then the same protocol 
can still work with space bound 0(log(t(n))). Now, the maximum length of a single-round can be 
determined by the verifier since it can count t{\x\) in this case and can terminate the computation 
with decision of "rejection" if the prover does not sent a halting configuration of A until then. We 
denote this new proof system as (P' , V). By using the idea given in the proof of Theorem G2 we can 
define a new verifier V" based on V such that it terminates the computation with the decision of 
"acceptance" when it observes the outcome of an auxiliary operation element, and so it implements 
only a single-round of (P' , V). 

The analysis of the proof system (P 1 , V") is as follows. The computation is terminated in every 
branch. If x G L, it is accepted by V" with probability 1 (due to perfect-completeness) by the help 
of P' . If x ^ L, the input is always rejected by V with some non-zero probability. 

As described in the proof of Theorem[5j we can easily construct a 0(log(t(\x\))) space-bounded 
qATM A' based on V", which recognizes L: The universal states of A' simulate V", and the 
existential states of A simulate the communications with all possible provers. If x £ L, there exists 
a finite accepting subtree whose existential moves correspond to the communication with P'. If 
x ^ L, any finite subtree contains at least one rejecting leaf. □ 

Acknowledgements. We would like to thank Andris Ambainis and A. C. Cem Say for their 
many helpful comments on some drafts of this paper. 
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A A review of previous private protocols 



In this part, we review the private protocols for obtaining the results given in Facts [2] and El 
which we will refer as the weak-protocol and the strong-protocol, respectively. (Since Fact [J] is a 
generalization of Fact [3] jDS92]. we omit its details.) The main idea behind both protocols for a 
given language is to simulate a fixed machine recognizing the given language: The prover sends 
to the verifier the computation of the simulated machine on a given input, which is a sequence of 
configurations starting from the initial configuration, and the verifier tries to verify the correctness of 
this sequence and then gives a decision with respect to the halting configuration sent by the prover. 
During the verification procedure, the following tasks can easily be checked deterministically: (i) 
each configuration has a correct format, and (ii) the sequence starts with the initial configuration 
and ends with a halting configuration. In the latter protocol, the length of each configuration is 
also checked to be at most linear. On the other hand, to check whether the prover sends a valid 
next configuration after each one is a non-trivial task. We will call this task successor-check and 
this is indeed where the private coin-flips come into play. 

Since a single computation requires many adjunctive successor-checks and each of them contains 
many (private) coin-flips, a decision on the input can only be given with a very small probability 
after passing a single computation. Therefore, the prover sends the computation repeatedly in an 
infinite loop. Depending on the machine and resources of the the verifier, either the verifier can 
always halt the computation with high probability or the protocol can run forever in some cases. 
For example, if the simulated machine never halts on the input and the prover honestly sends the 
corresponding computation, the verifier can never halt and give a decision. 

Now, we give some protocol specific details. We begin with the weak-protocol of Condon and 
Lipton [CL89j . In his seminal paper |Fre81j . Freivalds presented a two-way probabilistic finite 
automaton (pfa) recognizing language 

FRE = {a ni b ni a n2 b n2 ■ ■ ■ a nk b nk | m, . . . , n k > 0, k > 0} 

with bounded error. Based on Freivalds' algorithm, Condon and Lipton proposed a private protocol 
such that if a prover sends a member of FRE repeatedly to a one-way pfa verifier, then the verifier 
detects the memberships of the input with high probability. If the prover sends some nonmembers 
of FRE repeatedly to the same verifier, then the verifier gives a decision of rejection with high 
probability. Two-way finite automata with two-counters (2D2CA) are Turing-equivalent [Min67j . 
and their main configuration elements are the contents of the counters, which can be encoded unary. 
Then successor-checks on a computation of a 2D2CA can be implemented by the protocol given 
by Condon and Lipton. Let L be a Turing-recognizable language and T> be the 2D2CA recognizing 
it. For the members of L, the (honest) verifier sends finite valid configurations, and so the verifier 
accepts the input them with high probability. For the nonmembers of L, the verifier can only accept 
if the last configuration of the computation is an accepting one. This means that the computation 
contains at least one defect, and so the probability of rejection is greater than the probability of 
acceptance due to the defect. Since a prover can never sends a halting configuration, the protocol 
has a weak-soundness. 

In the case of the strong-protocol of Dwork and Stockmeyer |DS92j . the simulated machine is 
an 0(n) space-bounded ATM, say A. In order to simplify the proof, some inessential assumptions 
are made on A: Roughly, each existential or universal transition leads to exactly two branches, 
there is no consecutive two existential or universal branching, A uses only |x| + 2 space, A always 
halts exactly after 2 c ' :r branching steps by keeping a counter, and so A never enters a loop, where 
x is a given input and c is an appropriate constant. Note that the computation tree of A on x 
has 2 2c|a: ' leafs. The prover repeatedly sends the computation of some paths of this tree, in which 
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the nondeterministic choices are made by the prover and the universal choices are made by the 
verifier, i.e. the verifier flips a coin and sends the outcome to the verifier. The configurations on a 
computation are separated by $'s as 

• • • $Cj$Ci_|_l$Cj + 2$ • • • , 

where i > 0. Since each configuration of A on x is fixed length (\x\ + 3), the verifier can implement 
the successor-check by deterministically comparing the symbols at distance \x\ +4 by using its 
input head0 If there is not exactly one $ between two symbols, then the input is rejected by the 
verifier. The private part of the successor-check is that the verifier always selects the first symbol 
randomly and repeats this selection after each comparison. That is, if / > is the index of a 
selected symbol, then it is compared with (/ + \x\ + 4) th symbol, and then a new symbol with an 
index between (/ + \x\ + 4) + 1 and (I + \x\ + 4) + \x\ + 4 is selected. Since the protocol is private, 
the prover can never know which two symbols are compared. Thus, any defect on the computation 
can always be detected by the verifier with some probability, which is sufficiently greater than any 
accept probability. If there is no defect, the accepting probability is still very small so that a single 
rejecting probability on a leaf can always dominate the cumulative accepting probabilities from 
all the other leafs. (We omit the details here but the same issue is also detailed in the proof of 
Theorem O) Therefore, for the strings accepted by A, none of successor-check produces a rejecting 
probability, and so the verifier accepts the input exactly by help of a honest prover. For the strings 
rejected by A, if the input is not rejected by any successor-check, the input is rejected at least one 
path which is sufficient to dominate all the accepting decisions. Note that, if the prover never sends 
a halting configuration, the verifier detects infinitely many defects, which are sufficient to reject 
the input with probability 1, by using its input head. 

As seen from the details, the private methods used by the protocols are different. In the former 
one, the verifier privately collects statistical evidence from over the computations to decide their 
correctness. Moreover, two-sided error is necessary in this case due to Theorem [TJ In the latter 
case, the verifier can force the prover to send linear size configurations and then detects the defects 
directly. The latter protocol has also perfect-completeness. 

B The proof of Theorem [I] 

The proof of IPi(s(n)) C weak-IPi(s(n)) C ASPACE(2 20<s<n,, ) follows from Lemma[H(see below) and 
[CKS81] . where s(n) € fJ(log(n)) is space-constructible. 

We begin with a definition: The prover-verifier pair (P, V) is an unbounded- error IPS having 
perfect completeness for L if it has a perfect-completeness, i.e. satisfying condition (1'), and has 
the following soundness condition: 

2". for all x ^ L, and all provers P*, the probability that (P*, V) accepts x is less than 1. 

The classes defined by unbounded-error IPS having perfect completeness will be shown by I Pi,<i (•) • 

Lemma 4. For any space-constructible s{n) £ 0(log(n)), 

IPi,<i(s(n)) C DSPACE(2 2 ). 

14 If the simulated machine is s(n) £ cu(n) space-bounded, then log(s(n)) space-bounded verifier is sufficient for a 
similar check, where s is a space-constructible function. 



19 



Proof. Let L £ IPi ) <i(s(n)). Then there exists an unbounded-error IPS having perfect-completeness 
(P, V) for L. We will show that a DTM can recognize L by using triple-exponential time in s{n). 

Let x be an input string. Without loss of generality, we assume that the communication alphabet 
contains exactly two symbols {0, 1}. We represent the configuration set of V on x as Cy(x), whose 
size is exponential in s(|x|). We classify the configurations into five groups: 

1. read: the ones in a reading state 

2. comm-0: the ones in a communication state ready to write on the communication cell 

3. comm-1: the ones in a communication state ready to write 1 on the communication cell 

4. acc: the ones in an accepting state 

5. rej: the ones in a rejecting state 

The computation tree of (P',V) on x can be infinite for a prover P'. On the other hand, 
having perfect completeness allow us to build a finite computation tree that concisely represents 
the computation of V on x and its communications with all possible provers (P*). First of all, 
we do not need to keep the probabilities of the configurations since the input is either accepted 
with probability 1 or with a probability less than 1. (We do not need the cumulative sums of the 
accepting and rejecting probabilities.) Secondly, the length of any halting path must be bounded 
by a certain number steps. If the computation does not halt, then V must enter an infinite loop. 
An infinite loop, in our case, can either contributes to a halting path or independent from the other 
parts of the computation. We visualize both cases in Figure [2J The former case can be seen as a 
part of the halting path since the probability of being in the loop approaches to zero and the halting 
path is re-traversed with the decreasing probability after each cycle. However, the probability of 
being in the loop remains the same in latter case, and so it should be replaced with a rejecting 
path if detected. 




Figure 2: Two cases of infinite loops 

We denote our finite tree 7y(x). (Note that we do not specify any prover since this tree 
represent all possible communication scenarios.) The structure and evaluation of 7v(x) is similar 
to the computation tree of an ATM. The main difference of Tv{x) is that a node can take three 
different values instead of two values, which are originally true and false. We give the details of 
how Tv{x) can be constructed below. 

Since the protocol is private, we keep the configurations that follow the same communication 
strategy together. Therefore, each node of l~v{x) represents a subset of Cy (x). The root represents 
the initial configuration. We have four different types of inner nodes, i.e. 

READ-COMM, COMM-01, COMM-0, and COMM-1, 

and three different types of leafs, i.e. 
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ACC, RE J, and LOOP. 

A READ-COMM node, say RC, is a node that contains at least one read configuration and may 
contain some comm-0 or comm-1 configurations. The child node(s) of RC is (are) determined as 
follows: Each read configuration in RC divides into at most two child configurations in a single 
step. 

• If the child is an acc (a rej) configuration, then an ACC (a rej) leaf is created and connected 
to the RC. 

• If the child is a read configuration which is identical to a read configuration in RC, then a 
LOOP leaf is created and connected to RC. 

• In any other case, each child should be one of a read (not in RC), a comm-O, or a comm-1 
configuration. All these children with the previous comm-0 or comm-1 configurations form a 
new node and connected to RC. 

The type of the new node given in the last item is determined conditionally. If its depth (in 7y{x)) 
exceeds a certain number (2l Cv ( x ) - the total number of all subsets of Cy{x)), it becomes a LOOP 
leaf since it must be a repetition of a previous node along the same path. 

Suppose that the depth of the new node does not exceed this number. If it contains at least 
one read configuration, then it becomes a READ-COMM node again. If it contains both comm-0 and 
comm-1 configurations, then it becomes a COMM-01 node. If it contains only some comm-0 (comm-l) 
configurations, then it becomes a COMM-0 (comm-1) node. 

For each COMM-01 node, say C01, two new nodes are created and connect to C01. One of them 
becomes a COMM-0 node that contains all comm-0 configurations of C01. The other one becomes a 
COMM-1 node that contains all comm-1 configurations of C01. Both COMM-0 and comm-1 are the 
communication nodes. We give the details for a COMM-0, say CO, node. (The situation is exactly 
the same for a COMM-1 node.) Let c be a configuration in CO. In c, the verifier writes on the 
communication cell, and then receives or 1. Since we consider all possible communications, there 
are two next configurations evolved from c in a single step, say cq and c±. If cq (c\) is an acc or 
a rej configuration, then an ACC or a REF leaf is created, respectively, and connected to the CO; 
or if Co (ci) is a comm-0 configuration which is identical to a comm-0 configuration in CO, then a 
LOOP leaf is created and connected to CO. Otherwise, all co's and ci's are collected into two new 
nodes and then connected to CO. The types of the new nodes are determined as explained above. 
We completed how 7v(x) can be constructed. 

Now, we describe how Tv{x) can be evaluated. We associate each inner node with "A" or 
"V" operator: read-COMM and COMM-01 are associated with "A" (universal choice), and COMM-0 
and COMM-1 are associated with "V" (nondeterministic choice). These operators determines the 
value of a node from the values of its children. There are three types of values: true, false, and 
loop[depth], where depth is a numeric value. Obviously, any ACC (rej) leaf takes the value of true 
(false). Any LOOP leaf takes the value of loop with a depth value that represent the smallest depth 
of the repeated node. 

If the computation tree just contains true and false values, then its evaluation becomes trivial 
(exactly the same as alternation). The non-trivial part is how to include the loop into the evaluation. 
Suppose that a node associated with "A" has k > child/children, whose values are represented 
by vi, . . . , Ufc. The value of the node can be calculated as follows: 

vi A (v 2 A • • • (v k -2 A (ufc_i A v k ))), 
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where binary relation "A" is denned as follows: 



A 


true 


false 


loop[di] 


true 


true 


false 


true 


false 


false 


false 


false 


loop[d 2 ] 


true 


false 


loop[mm{di, d 2 }] 



Since it is a universal choice, any false value beats all the other values. Any true value beats any 
loop value, since this loop contributes the accepting path. Between two loop values, we select the 
one having smaller depth. The value of a "V" node can be calculated in a similar way with its 
specific rules: 



V 


true 


false 


loop[di] 


true 


true 


true 


true 


false 


true 


false 


loop[di] 


loop[d2] 


true 


loop[d2] 


loop[mm{di, 62}] 



Since it is an existential (nondeterministic) choice, any true value beats all the other values. Any 
loop value beats any false value, since the corresponding loop may contribute an accepting path in 
a lower depth. Between two loop values, we again select the one having smaller depth. The last 
thing about the evaluation is that if a node takes value of loop and the depth of the loop refers to 
this node, then the value of the node is changed to false since this loop does not contribute any 
accepting path. The value of the root is the value of the tree. 

In case of x G L, we know that there exists a nondeterministic strategy (corresponding to the 
communication with P) on the tree such that it does not lead to any rejecting path, and any infinite 
loop must contribute some accepting paths. Therefore, the value of the root is set to true. 

In case of x ^ L, we know that for every nondeterministic strategy (corresponding to the com- 
munication with P*), there must be a nonzero rejecting path or a nonzero looping path (not con- 
tributing any accepting path) that dominates all the other opponent values during the evaluation. 
Therefore, the value of the root is set to false. 

A DTM can construct and evaluate 7y (x) in a straightforward way. Since the depth of the tree 
is 2l c vO B )l, the total running time of the DTM is double-exponential in |Cy(x)|. Since |Cy(a;)| is 
exponential in s(|x|), then the total running time becomes triple-exponential in s(|x|). □ 

C A constant-space qAM protocol for SUBSET-SUM 

In this appendix, we present a qAM system having a finite-state verifier for the well-known NP- 
complete language SUBSET-SUM, which is the collection of all strings of the form S'SaiS . . . $a n $ such 
that S and the dj's are numbers in binary (1 < i < n), and there exists a set / C {1, . . . ,n} 
satisfying Yliei a i = ^ where n > 0. 

Lemma 5. SUBSET -SUM G qAM(l). 

Proof. We assume that the input to be of the form S'SaiS . . . $a n $, where S, the a^'s are numbers 
in binary (1 < i < n), and n > 0. (If not, the input is immediately rejected.) The input is written 
between two # symbols on the input tape and its head is not allowed to cross these boundaries. 

The main idea is that the verifier scans the input from left to right in an infinite loop and firstly 
encodes S, and then subtracts the encoding of each of the a^s selected by the prover, in some 
amplitudes of the states on the quantum register. And at the end of the loop (round), the verifier 
tests whether the result is zero or not (described later). Since our encoding procedure works by 
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reducing the amplitude with a constant in each step, the process can successfully be ended with 
an exponentially small probability depending on the length of the input. Therefore, a new round 
is initiated with remaining huge probability. 

The register has 3 states, {(/i,</2> 13}- Each round is composed by five parts, described below. 
The details of superoperators applied in each round are given in Figure where each outcome 
is given under the operation element. The actions associated to each outcome are as follows: (i) 
The input head is moved forward if outcome "/" is observed, (ii) the input is accepted (rejected) 
if outcome "a" ("r") is observed, and (iii) a new round is initiated if outcome "i" is observed. 

1. The finite register is initialized on symbol |^o) = (10 0) T . 

2. S is encoded into the amplitudes of \q2). £ a is applied on the quantum register when reading 
a 6 {0, 1}. Then, E% is applied on the quantum register when reading $. 



3. Each en (1 < i < n) is encoded into the amplitude of 
register when reading a £ {0, 1}. 



Q3) 



£' a is applied on the quantum 



4. If an a,i (1 < i < n) is selected by the prover on symbol $, it is subtracted from the number 
represented by the amplitude of \q2}'- £'% is applied on the quantum register. If it is not 
selected, is applied on the quantum register. Note that, the amplitude of {q^) is set to 
after each of these transformations. 

5. The decision is given on is applied on the quantum register when reading 
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Figure 3: The details of superoperators used by the qAM system for SUBSET-SUM 

Let w be the input and T be the cumulative sum of selected a^s by the prover. Then, the state 
of the register before reading # becomes 



«l> = 



S-T 
k 1 



After applying the input is rejected with probability 



2|ui|+2 



(35 - 3T) 2 
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which is at least 9 (g) if 5 7^ T and is exactly equal to if S = T. On the other hand, the 

input is always accepted with probability (i) 2 '" 1 ' -1-2 . Therefore, if w € SUBSET-SUM, there exists 
a prover such that it is accepted exactly, and if w ^ SUBSET-SUM, whatever the prover says, it is 
rejected with a probability at least yg. The error bound can be reduced to any desired value by 
using probability amplification. □ 

D A time-bound for absolutely-halting space-bounded quantum 
Turing machines 

The first space-bounded QTM model was introduced by Watrous [Wat98 , Wat99b] , and he showed 
that any such s(n) space-bounded QTM that always halts on every input can run at most 2°( s ( n ^ 
steps, where s(n) £ f2(log(ra)). Since the nonhalting part of such a model can always be in a single 
pure (quantum) state, the same result cannot be directly applicable to the QTMs whose halting 
part can be in a mixture of some pure states (mixed-state). The qATM introduced in Section 0] 
and the models introduced in |Wat031 lYSllbl lvMW12j are some examples for the latter case. 

On the other hand, since any mixed-state and the operator(s) applied to it can be represented 
by a single vector and a single matrix, respectively, the result given by Watrous can be extended 
to general case. We will provide an explicit proof of this result below. 

A QTM can have both classical and quantum parts. Let Ai be such a space-bounded QTM and 
x be an input. A standard configuration of Ai on x is a pair of (c, \d)), where c is a configuration of 
the classical part and \d) is a (standard) basis vector of the quantum part. During the computation, 
Ai can be in some mixture of (c, \ip)ys, where each can be either a basis vector or a superposition 
of some basis vectors. 

Theorem 7. Let N be the number of the standard configurations of an absolutely-halting space- 
bounded QTM Ai on a given input x. Then, Ai can run at most N 2 steps on x. 

Proof. In space-bounded quantum computation, the computation is regularly observed whether it 
is terminated or continued, and then the observed part is normalized. The nonhalting part of Ai 
on x can be represented by an N x iV-dimensional density matrix. Since we consider whether this 
matrix is equal to zero matrix or not, we can omit the normalization part. Based on the local 
transitions of Ai, we can defined some finite, say k, N x N matrices {E\, . . . ,E^} that represent 
one step transformation of the nonhalting part. Thus, we obtain the following matrix sequence 
that represent the nonhalting part for each step: 

V Q ,Vx,V2, ... , (4) 

where vq is the initial one and V{ represents the i th (i > 0) one obtained after i th steps, which is 
calculated as: 

k 
j'=i 

If Ai halts on every input absolutely, there must be an index i' such that vy = 0. As pointed out 
above, the sequence given in Eq. H] can be represented by vectors, and each of them (except the 
initial one) can be obtained by applying a single operator (matrix) to the previous vector in the 
sequence. That is, based on vq and {E\, . . . , E^}, we define an A^ 2 -dimensional vector, say Vq, and 
iV 2 x iV 2 -dimensional matrix, say E, respectively, and then Eq. [5] turns out be as follows: 

v ,v 1 ,v 2 ,... , 
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where 

Vi = Evi-i (i > 0). 

We refer the reader to Page 73 of [Wat03] for the details of this conversion. Now, we will show that 
i' cannot be bigger than TV 2 due to the following fact. 

Fact 6. For any m- dimensional vector u, if A m u ^ 0, then A m+:J u ^ 0, where A is an m x Tri- 
dimensional matrix and j > of^l 

Proof. The proof can be easily obtained from the following well-known relation: 

ker(A) C ker(A 2 ) C • • • C ker(A m ) = ker(A m+1 ) = ker(A m+2 ) = ■■■ 
That is, if u is not in ker{A m ), then u cannot be in ker(A m+J ) for any j > 0. □ 

Thus we can say that if Ev^2 ^ 0, then Vj^2 + j cannot be equal to zero for any j > 1, i.e. M 
cannot halt absolutely on x. Therefore, i' cannot be bigger than iV 2 , which is a quadratic bound 
in terms of the number of configurations. □ 

Corollary 6. Any s(n) £ 0(log(n)) space-bounded QTM that always halt on every input can run 
at most 2°( s ( n )) steps. 
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